VendorsSamsungandroidall versions
Vulnerabilities

Samsung Android 9.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

511CVEs
CVE-2023-52432
Improper input validation in IpcTxSndSetLoopbackCtrl in libsec-ril prior to SMR Sep-2023 Release 1 allows local attackers to write out-of-bounds memory.
Published 2024-03-05 · Analyzed
7.1EPSS 0.002
CVE-2025-21015
Path Traversal in Document scanner prior to SMR Aug-2025 Release 1 allows local attackers to delete file with Document scanner's privilege.
Published 2025-08-06 · Analyzed
7.1EPSS 0.002
CVE-2025-20988
Out-of-bounds read in fingerprint trustlet prior to SMR May-2025 Release 1 allows local privileged attackers to read out-of-bounds memory.
Published 2025-06-04 · Analyzed
7.1EPSS 0.002
CVE-2024-49401
Improper input validation in Settings Suggestions prior to SMR Nov-2024 Release 1 allows local attackers to launch privileged activities.
Published 2024-11-06 · Analyzed
7.1EPSS 0.002
CVE-2024-20879
Improper input validation vulnerability in libsavscmn.so prior to SMR Jun-2024 Release 1 allows local attackers to write out-of-bounds memory.
Published 2024-06-04 · Analyzed
7.1EPSS 0.001
CVE-2026-21058
Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Published 2026-08-10 · Analyzed
7.1EPSS 0.001
CVE-2024-34638
Improper handling of exceptional conditions in ThemeCenter prior to SMR Sep-2024 Release 1 allows local attackers to delete non-preloaded applications.
Published 2024-09-04 · Analyzed
7.1EPSS 0.001
CVE-2024-34679
Incorrect default permissions in Crane prior to SMR Nov-2024 Release 1 allows local attackers to access files with phone privilege.
Published 2024-11-06 · Analyzed
7.1EPSS 0.001
CVE-2025-21050
Improper input validiation in Contacts prior to SMR Oct-2025 Release 1 allows local attackers to access data across multiple user profiles.
Published 2025-10-10 · Analyzed
7.1EPSS 0.001
CVE-2023-21490
Improper access control in GearManagerStub prior to SMR May-2023 Release 1 allows a local attacker to delete applications installed by watchmanager.
Published 2023-05-04 · Modified
7.1EPSS 0.001
CVE-2026-21059
Improper export of android application components in Samsung Contacts prior to SMR Aug-2026 Release 1 allows local attackers to delete file with Samsung Contacts' privilege.
Published 2026-08-10 · Analyzed
7.1EPSS 0.001
CVE-2023-21474
Intent redirection vulnerability in SecSettings prior to SMR Apr-2022 Release 1 allows attackers to access arbitrary file with system privilege.
Published 2025-09-03 · Analyzed
7.1EPSS 0.001
CVE-2025-21080
Improper export of android application components in Dynamic Lockscreen prior to SMR Dec-2025 Release 1 allows local attackers to access files with Dynamic Lockscreen's privilege.
Published 2025-12-02 · Analyzed
7.1EPSS 0.001
CVE-2026-21104
Heap-based buffer overflow in KnoxVault trustlet prior to SMR Sep-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2026-09-09 · Analyzed
7.1EPSS 0.001
CVE-2026-21100
Improper access control in SystemUI prior to SMR Sep-2026 Release 1 allows local attackers to launch arbitrary activity.
Published 2026-09-09 · Analyzed
7.1EPSS 0.001
CVE-2026-20980
Improper input validation in PACM prior to SMR Feb-2026 Release 1 allows physical attacker to execute arbitrary commands.
Published 2026-02-04 · Analyzed
7.0EPSS 0.002
CVE-2026-21064
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
Published 2026-08-10 · Analyzed
7.0EPSS 0.001
CVE-2026-20977
Improper access control in Emergency Sharing prior to SMR Feb-2026 Release 1 allows local attackers to interrupt its functioning.
Published 2026-02-04 · Analyzed
6.9EPSS 0.001
CVE-2026-21023
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
Published 2026-04-29 · Analyzed
6.9EPSS 0.001
CVE-2026-21022
Improper handling of insufficient permissions in Routines prior to SMR May-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-05-13 · Analyzed
6.9EPSS 0.001
CVE-2026-21025
Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.
Published 2026-06-05 · Analyzed
6.9EPSS 0.001
CVE-2023-21513
Improper privilege management vulnerability in CC Mode prior to SMR Jun-2023 Release 1 allows physical attackers to manipulate device to operate in way that results in unexpected behavior in CC Mode under specific condition.
Published 2023-06-28 · Modified
6.8EPSS 0.004
CVE-2023-42533
Improper Input Validation with USB Gadget Interface prior to SMR Nov-2023 Release 1 allows a physical attacker to execute arbitrary code in Kernel.
Published 2023-11-07 · Modified
6.8EPSS 0.004
CVE-2024-20865
Authentication bypass in bootloader prior to SMR May-2024 Release 1 allows physical attackers to flash arbitrary images.
Published 2024-05-07 · Analyzed
6.8EPSS 0.003
CVE-2026-20982
Path traversal in ShortcutService prior to SMR Feb-2026 Release 1 allows privileged local attacker to create file with system privilege.
Published 2026-02-04 · Analyzed
6.8EPSS 0.003
CVE-2023-42577
Improper Access Control in Samsung Voice Recorder prior to versions 21.4.15.01 in Android 12 and Android 13, 21.4.50.17 in Android 14 allows physical attackers to access Voice Recorder information on the lock screen.
Published 2023-12-05 · Modified
6.8EPSS 0.003
CVE-2024-20803
Improper authentication vulnerability in Bluetooth pairing process prior to SMR Jan-2024 Release 1 allows remote attackers to establish pairing process without user interaction.
Published 2024-01-04 · Modified
6.8EPSS 0.003
CVE-2024-20880
Stack-based buffer overflow vulnerability in bootloader prior to SMR Jun-2024 Release 1 allows physical attackers to overwrite memory.
Published 2024-06-04 · Analyzed
6.8EPSS 0.003
CVE-2026-21009
Improper check for exceptional conditions in Recents prior to SMR Apr-2026 Release 1 allows physical attacker to bypass App Pinning.
Published 2026-04-13 · Analyzed
6.8EPSS 0.002
CVE-2023-21472
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.
Published 2025-09-03 · Analyzed
6.8EPSS 0.002
CVE-2023-21473
Improper input validation with Exynos Fastboot USB Interface prior to SMR Apr-2023 Release 1 allows a physical attacker to execute arbitrary code in bootloader.
Published 2025-09-03 · Analyzed
6.8EPSS 0.002
CVE-2026-21021
Improper input validation in Routines prior to SMR May-2026 Release 1 allows physical attackers to launch privileged activity.
Published 2026-05-13 · Analyzed
6.8EPSS 0.002
CVE-2026-21063
Improper export of android application components in AppLock prior to SMR Aug-2026 Release 1 allows physical attackers to bypass app lock function.
Published 2026-08-10 · Analyzed
6.8EPSS 0.002
CVE-2025-21047
Improper access control in KnoxGuard prior to SMR Oct-2025 Release 1 allows physical attackers to use the privileged APIs.
Published 2025-10-10 · Analyzed
6.8EPSS 0.002
CVE-2025-21073
Insecure default configuration in USB connection mode prior to SMR Nov-2025 Release 1 allows privileged physical attackers to access user data. User interaction is required for triggering this vulnerability.
Published 2025-11-05 · Analyzed
6.8EPSS 0.002
CVE-2026-21103
Path traversal in GalaxyDiagnostics prior to SMR Sep-2026 Release 1 allows physical attackers to access files with system privilege.
Published 2026-09-09 · Analyzed
6.8EPSS 0.002
CVE-2025-21032
Improper access control in One UI Home prior to SMR Sep-2025 Release 1 allows physical attackers to bypass Kiosk mode under limited conditions.
Published 2025-09-03 · Analyzed
6.8EPSS 0.002
CVE-2026-21007
Improper check for exceptional conditions in Device Care prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Knox Guard.
Published 2026-04-13 · Analyzed
6.8EPSS 0.002
CVE-2026-21003
Improper input validation in data related to network restrictions prior to SMR Apr-2026 Release 1 allows physical attackers to bypass the restrictions.
Published 2026-04-13 · Analyzed
6.8EPSS 0.002
CVE-2026-21018
Out-of-bounds write in SveService prior to SMR May-2026 Release 1 allows local privileged attackers to execute arbitrary code.
Published 2026-05-13 · Analyzed
6.8EPSS 0.002
← Prev6 / 13Next →